Symptoms

BIG-IP sends extra messages in the audit log whenever you make a change to a user's role (when changing a user's role to or from Administrator/admin). When that happens, there are extra 'create_if' messages sent for all the users that have the Administrator role in the system, for example:
01070417:5: AUDIT - user admin - transaction #3153035-5 - object 0 - modify { userdb_entry { userdb_entry_name "admint2" userdb_entry_shell "/sbin/nologin" } } [Status=Command OK].

Impact

There may be extra messages in the audit log whenever a change is made to a BIG-IP system user's role

Conditions

-- LTM and ASM provisioned.
-- RADIUS authentication.

Workaround

You can correct this issue by forcing an overwrite sync operation.
For instructions, see K13887: Forcing a BIG-IP device group member to initiate a ConfigSync operation (https://support.f5.com/csp/article/K13887).